
FireEye identified APT’s primary targets as US Defense Industrial Base (DIB), and businesses in the construction, engineering, technology, and telecom sector. Why MSPs are a high-payoff targets for espionage Only recently has MSPs been a focus for such treat organizations. It is hard to overlook the attractiveness of an MSP, its network, and the vast array of service offerings it may provide.

Since MSPs operate with a high-level control of their clients, once this is hacked, the path of the actor is straightforward. Two mains exploits hackers use against MSPs Provides enterprise services or cloud hosting.Stores significant quantities of client data on MSPs internal infrastructure.Unfettered and direct access to their clients’ networks.Remote management of customer IT and end-user systems.Thus, leaving MSPs and their clients vulnerable for greater amounts of intellectual property or sensitive data to be stolen.Īttractive features for hackers, does your MSP offer the following? Once the gateway is open, it allows them to move on to other networks and it’s end-points. This may sound like old news to you, but the matter of fact is, hackers use phishing because they succeed. Spear phishing, the exploit that APT10 utilized, is specifically targeted and personalized towards the victim themselves.Phishing is a generalized exploit through email where the threat actor masquerades themselves as a trustworthy organization to broadly target a mass group of victims.Two variations of phishing exist: phishing and spear phishing.
